Skip to main content
Akmostafa
Explorer
May 19, 2023
Question

SAML session timeout

  • May 19, 2023
  • 1 reply
  • 3469 views

Hello team.

I am testing using FAC as SAML idb, currently my test is running on administrator access to Fortigate.

 

The "Login session timeout" setting under SAML idb - General : is kept on the default 480 mins.

 

However, each time I hit the Fortigate IP and then being redirected to FAC login, I am presented the login screen to enter my credentials.

 

Does the admin session time out on Fortigate affects the SAML request being send to FAC and enforcing a different time out other than the "login session timeout" configured on FAC?

Otherwise how to tweak this behavior so that the user can access the resource for longer time without being prompted to login every 5 mins.

 

Thank you.

Ahmed

1 reply

ebilcari
Staff
Staff
May 19, 2023

As explained here: https://docs.fortinet.com/document/fortiauthenticator/6.5.1/administration-guide/817031/saml-idp

Two possibilities:

  • The user's browser already has valid SAML assertions, so it sends them to the SPs web server (FGT). The web server (FGT) uses them to grant or deny access to the service. SAML authentication stops here.
  • The user's browser doesn't have valid SAML assertions, so the SPs web server (FGT) redirects the browser to the SAML IdP (FAC).

If you change browser or log off the user this assertions are destroyed. As long as you get redirected to FAC it means that the browser doesn't have valid assertions anymore.

 

Maybe admin session timeout of the FGT is treated as a log off for SAML. In my lab I have this profile applied:

edit "prof_admin"
set admintimeout-override disable

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.